webphantom[.]online
Forensic brief
Read full brief
PhishDestroy identifies webphantom.online as an active crypto drainer impersonating the Phantom brand, leveraging a Solana Drainer kit to target cryptocurrency users. This domain was flagged due to its malicious infrastructure and deceptive branding, which closely mimics the legitimate Phantom ecosystem. The threat actor behind this domain employs a sophisticated drainer kit designed to siphon funds from unsuspecting victims by exploiting trust in the Phantom wallet ecosystem.
This domain resolves to IP address 188.114.97.3 and is registered through Hosting Concepts B.V. d/b/a Registrar.eu. The domain was created on February 27, 2026, and currently operates with a Let’s Encrypt SSL certificate, adding a veneer of legitimacy. Despite its recent creation, webphantom.online has evaded detection with a VirusTotal score of 0/95, indicating no antivirus or security vendor has flagged it as malicious at the time of analysis.
Additionally, this domain remains unblocked by Google Safe Browsing (GSB) and has not yet been added to major threat intelligence blocklists, which increases its potential reach and effectiveness. The domain is currently active and poses a high risk to users who may mistakenly interact with it while seeking legitimate Phantom services. PhishDestroy strongly advises users to exercise extreme caution and verify the legitimacy of any domain claiming to be associated with Phantom.
While immediate action has been taken to flag this domain within PhishDestroy’s systems, the lack of detections on VirusTotal and absence from blocklists suggest this threat remains under the radar for many security tools. Users are urged to cross-reference domains with official Phantom channels and rely on PhishDestroy’s verification tools to mitigate the risk of falling victim to this crypto drainer.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Hosting Concepts B.V. d/b/a Registrar.eu
Technical details
Public blocklist status
Technologies
Technologies · 7 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of webphantom.online
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@ d/b/a registrar.eu
Registrar: Hosting Concepts B.V. d/b/a Registrar.eu Case: PD-
Embed this report
About this report
About this report: webphantom.online
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 2 public blocklists.
The site displays a page titled “Вход”.
webphantom.online has been flagged by 5 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.